Privacy Policy

Last updated: July 9, 2026 · DRAFT

This is a draft template for structure only — not legal advice and not binding. Have your legal counsel review and finalize before launch.

1. Introduction

This Privacy Policy describes how CloudCerta collects, uses, and protects information when you use our cloud-security assurance platform. It applies to account holders and their authorized users across all connected tenants. By using CloudCerta, you agree to the practices described here.

2. Information we collect

We collect account details you provide (such as name, email, and organization), usage and telemetry data generated as you interact with the platform, and cloud resource metadata gathered during scans of your connected cloud accounts. We do not collect the contents of your business data stored in those accounts — only configuration and metadata relevant to security assessment.

3. How we use information

We use collected information to provide and operate the service, evaluate your cloud posture and generate findings, scoring, and reports, secure and improve the platform, communicate with you about your account, and comply with legal obligations. We do not use your scan or resource metadata to train models without your explicit consent.

4. Legal bases for processing

Where the GDPR applies, we process personal data on the bases of contractual necessity (to provide the service you signed up for), legitimate interests (such as securing the platform and preventing abuse), and compliance with legal obligations. Where required, we rely on your consent, which you may withdraw at any time.

5. Your cloud data & read-only access

CloudCerta connects to your cloud environment via a read-only cross-account IAM role secured with a unique External ID that you configure yourself. CloudCerta never stores your cloud credentials or access keys — only scan and resource metadata produced during assessment is retained. Access sessions are time-limited, scoped strictly to read-only permissions, and never used to modify your infrastructure.

6. Sharing & subprocessors

We do not sell your data. We share information with subprocessors who help us operate the platform (such as cloud infrastructure and email-delivery providers) under contractual confidentiality and data-protection obligations, and with third parties when required by law or to protect the rights and safety of CloudCerta and its customers. Findings and account data are never shared outside your tenant.

7. Data retention

We retain account information for as long as your account is active and scan/resource metadata for the period needed to provide historical trends, reporting, and audit history. When you close your account or request deletion, we delete or anonymize your data within a reasonable period, subject to legal or contractual retention requirements.

8. Security

We protect data with encryption in transit and at rest, strict tenant isolation so that one customer's data is never accessible to another, and least-privilege access controls for our personnel and systems. No method of transmission or storage is completely secure, but we continuously work to protect your information.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Residents of the EEA/UK (GDPR) and California (CCPA) have specific statutory rights; to exercise any of these rights, contact us using the details below and we will respond within the timeframe required by applicable law.

10. Cookies & tracking

We use essential cookies to keep you signed in and to remember your preferences, and limited analytics cookies to understand how the platform is used and to improve it. We do not use third-party advertising trackers. You can control cookies through your browser settings, though disabling essential cookies may affect the service.

11. International data transfers

Your information may be transferred to and processed in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognized under applicable data protection law.

12. Children's privacy

CloudCerta is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our practices or applicable law. We will post the updated policy with a revised “Last updated” date, and material changes will be communicated to account administrators. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

14. Contact

Questions about this Privacy Policy or requests regarding your personal data can be sent to privacy@cloudcerta.com.